An important update about your data

An important update about your data

31. July 2026

3 minutes

We recently identified a security issue that affected some of our customers’ data. We’re writing about it openly, because that’s the right thing to do, and because we want you to know how to protect yourself.

What happened

Due to a configuration error on our side, the documents were generated to a space reachable via a direct address (URL) without application-level authorisation. The indexing of some of these addresses by external search engines occurred due to a misconfiguration in the layer that handles the delivery and protection of our website. Once such an address was found, the invoice could be downloaded without any identity verification.

Between 1 and 2 July 2026, an unauthorised party used this to locate and download a portion of the files before we secured access. We identified the problem on 8 July and fixed it the same day.

What data was involved

The affected invoices contained customer names, addresses, phone numbers, email addresses, and order details. For business customers, they also included company ID (IČO).

They did not include:

  • Any payment or card details. We don’t store these; they’re handled by our payment provider.
  • Any account passwords.

What we’ve done

  • Secured all invoice documents behind authentication the same day.
  • Successfully identified and removed the vulnerability, and hardened our systems.
  • Reported the incident to the Slovak data protection authority (ÚOOÚ) and the National Security Authority (NBÚ).
  • Brought in an external cybersecurity and forensics specialist to review everything.
  • Contacted all affected customers directly by email.

What this means for you, and how to stay safe

The main risk from this kind of data is targeted scam messages. Someone could use your name and order details to make a fake message look convincing. Please stay alert to any email, call or text claiming to be from NEBBIA.

How to know it’s really us

  • We only email from @nebbia.biz, @nebbia.fitness or @nebbia.com. Any other address is not us.
  • Our only official sites are nebbia.fitness, nebbia.com, nebbia.sk, nebbia.cz, nebbia.it, nebbia.hu, nebbia.de and nebbia.biz. Check the link before you click.
  • We send SMS only about offers and news. We never ask for passwords, payment or personal details by text. If a message claiming to be NEBBIA asks you to confirm details or pay, it is not from us.
  • We will never ask you for your password or full card details.

Our commitment

This shouldn’t have happened. We’ve fixed it, we’ve strengthened how we protect your data, and we’re being open with you about all of it. If you have any questions, write to us at [email protected] and a real person will answer.

Martin Pecko
CEO, NEBBIA

An authentic approach to design

Approved by athletes

Official partner of Olympia